Symfony是Symfony组织开源的一个用于 Web 和控制台应用程序的 PHP 框架以及一组可重用的 PHP 组件。 Symfony 6.1.0之前版本至6.4.41之前版本、7.0.0-BETA1之前版本至7.4.13之前版本和8.0.0-BETA1之前版本至8.0.13之前版本存在处理逻辑错误漏洞,该漏洞源于UrlSanitizer::parse()函数拒绝未经过百分号编码的原始双向格式化字符并使用仅ASCII空白检查,导致经过清理的URL可能保留下游消费者可解码或显示的视觉欺骗字符。以下版本受
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| symfony | html-sanitizer | >= 6.1.0, < 6.4.41 |
affected |
>= 7.0.0-BETA1, < 7.4.13 |
affected | ||
>= 8.0.0-BETA1, < 8.0.13 |
affected | ||
| symfony | symfony | >= 6.1.0, < 6.4.41 |
affected |
>= 7.0.0-BETA1, < 7.4.13 |
affected | ||
>= 8.0.0-BETA1, < 8.0.13 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| symfony | symfony | >= 6.1.0, < 6.4.41 | - |
|
| symfony | html-sanitizer | >= 6.1.0, < 6.4.41 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45133 | Symfony: [Yaml] Harden the parser when handling untrusted input | |
| CVE-2026-46644 | symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only | |
| CVE-2026-48761 | Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, | |
| CVE-2026-48736 | Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-c | |
| CVE-2026-48747 | Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signatu | |
| CVE-2026-48489 | Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access t | |
| CVE-2026-48784 | Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Gener | |
| CVE-2026-47212 | Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauth | |
| CVE-2026-45068 | Symfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address | |
| CVE-2026-45071 | Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = | |
| CVE-2026-47767 | Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/AP | |
| CVE-2026-45075 | Symfony: HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureVali | |
| CVE-2026-45304 | Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansio | |
| CVE-2026-45063 | Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator | |
| CVE-2026-45070 | Symfony: Email Header Injection via Non-Token Characters in Mime Parameter Names | |
| CVE-2026-45756 | Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Wi | |
| CVE-2026-45754 | Symfony: Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthentica | |
| CVE-2026-45069 | Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims | |
| CVE-2026-45753 | Symfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — javascr | |
| CVE-2026-45072 | Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File R |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet